Swaplanguage
swaplanguage.comSwap Language is a Danish (EU-based) language-learning and language-exchange platform serving individuals and companies. Its policy documents are written in plain, non-legalistic prose and assert GDPR coverage, EU-only data storage in Amsterdam, and use of Stripe for payments. However, the documents are silent or vague on many core protections: there is no named security certification (SOC 2, ISO 27001), no explicit data-retention schedule beyond a 3-year anonymization rule and a 26-month Google Analytics window, extensive collection of profile/behavioral data used for marketing, and a Privacy Policy that reserves the right to change with 180-day delayed effectiveness and no direct notice. The service processes adult users (18+) but does collect a range of PII (location, IP, GPS, device data, chat content). For professional or business use, review is advised before submitting sensitive or proprietary data.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The documents do not contain an explicit statement assigning ownership of user-submitted data (profile text, chat messages, references). The Terms address acceptable-use restrictions and Swap Language's own trademarks/content but are silent on who owns user-generated content, which is itself a gap.
Output Data Ownership
The service delivers lessons, quizzes and video material rather than AI-generated outputs, and the Terms grant users only a limited license to access that content. The documents do not address ownership of any output produced by or for the user, so this remains unclear.
Training Data Usage
The documents make no mention of AI or machine-learning model training, nor of using user inputs to train models. The product does not appear to be AI-first, but the silence means there is no explicit commitment either way; data is described as used for service improvement and marketing.
Data Retention & Deletion
Users can request full deletion by email and can deactivate/delete their profile in settings; chat messages are deleted upon profile deletion. Retention is otherwise governed by a 3-year inactivity anonymization rule and a 26-month Google Analytics window, but there is no comprehensive retention schedule or deletion SLA.
Third-Party Data Sharing
The Privacy Policy states data is not shared with outside companies except with user consent or for legal reasons, which is user-favorable. However, the platform's core matching function inherently exposes profile data to other users, and payment data is shared with Stripe; the documents also reference third-party sellers in the purchase flow without naming them, warranting moderate caution.
Opt-Out Rights
The policy provides several concrete opt-out and control mechanisms: marketing sharing is opt-in, users can withdraw consent by deactivating their profile, can control profile visibility, and can request deletion. Cookies can be refused via the browser. These are meaningful, if not exhaustive, controls.
Compliance & Certifications
The vendor asserts it is subject to and protected by the GDPR and operates under Danish law, with EU-only physical storage in Amsterdam. However, no third-party attestations or certifications (SOC 2, ISO 27001, ISO 42001) are named, and sector-specific frameworks (FERPA, COPPA) are not addressed — though as an adults-only edtech tool, FERPA/COPPA relevance is limited. GDPR is claimed rather than independently attested.
Model Explainability & Auditability
The documents do not describe any AI/ML model, nor any explainability, auditability, or enterprise audit capabilities. As the product does not appear to be model-driven, this is largely not applicable, but the silence means no transparency guarantees exist.
Security Practices & Breach History
The policy discloses SSL/TLS encryption in transit and limited internal access to data, and confirms payment card data is handled by Stripe and not stored in full. However, there is no mention of encryption at rest, penetration testing, bug bounty, incident response, breach notification procedures, or a dedicated trust/security center; a referenced safety-and-trust page was inaccessible.
Enterprise vs. Consumer Risk Delta
The Terms distinguish Free Users, Subscribers, End consumers, and Companies (Pro plan), and describe differing billing, cancellation and scheduling rules by tier. However, the documents describe no difference in data handling, privacy protections, or security between free and paid/company tiers; the privacy commitments appear uniform.
Human Review of User Inputs
The vendor stores all chat messages and reserves the right to review content for moderation, harassment or unlawful behavior, and to delete profiles. It does not proactively review all content, but staff can access saved messages as evidence, so user communications are not private from the vendor.
Regulatory & Litigation Exposure
The documents address cooperation with authorities: Swap Language will disclose personal data to authorities under GDPR legal obligations and states it will contact police with information such as IP addresses in cases of fake information or harassment. No litigation history or disputes are disclosed.
PII & SPI Data Inventory
The service collects substantial PII — email, name, nationality, workplace/field, country of residence, profile pictures, IP/GPS/device location, device data, chat content, and payment method (via Stripe). Some fields (gender, nationality, education, occupation) approach sensitive categories and are explicitly used for marketing targeting, though most are disclosed with stated purpose. No highly sensitive SPI (health, biometrics, financial data beyond Stripe-handled cards) is collected.
Policy–Product Currency
The Terms carry a 'Last updated: 04.06.2026' date, well within 12 months of the 2026-09-10 analysis date, and the documents cover the product's core capabilities (courses, matching, chat, payments, company plans) visible in the product surface. However, the Privacy Policy has no discoverable effective date, and neither document mentions any AI/ML processing that a modern learning product might involve, so coverage of that dimension is unconfirmed; capping at YELLOW.
Cross-Document Consistency
Two documents were supplied (Privacy Policy and Terms of Service) and were compared. They are broadly consistent on GDPR coverage, Stripe payment handling, deletion via email, and Danish jurisdiction; no material or critical contradictions were identified between them.
You've read all 15 risk ratings for Swaplanguage. Create a free account to see the exact policy wording behind each rating.